
30 Days Free Trial WordPress Hosting
We love WordPress and it’s possibilities. Bring or buy your own domain and get a WordPress website with hosting free for 30 days and then only €3.82/month.
Click here and check it out.
- WPBeginner Spotlight 26: Form Analytics, More AI Tools, and Smarter SEO Monitoringby Editorial Staff on 31/07/2026 at 11:11
The main theme of this month’s WordPress news is measurement. Most of what shipped in July shows you something that your site was already doing without telling you. WPForms can now show which form field people abandon, and AIOSEO can tell you the day a… Read More » The post WPBeginner Spotlight 26: Form Analytics, More AI Tools, and Smarter SEO Monitoring first appeared on WPBeginner.
- What’s Coming in WordPress 7.1? (Features & Screenshots)by Editorial Staff on 27/07/2026 at 10:15
WordPress 7.1 beta is now available for testing, and we have been running it on our test sites for the past week. The official release is scheduled for August 19, 2026, timed with WordCamp US. While WordPress 7.0 rebuilt the admin and introduced the AI… Read More » The post What’s Coming in WordPress 7.1? (Features & Screenshots) first appeared on WPBeginner.
- Ultimate WordPress Spam Protection Guide – Step by Step (2026)by Editorial Staff on 17/07/2026 at 17:01
If you run a WordPress site, then you know that spam is a real annoying problem whether it comes to contact forms, WordPress comments, or user registrations. The good news is that stopping spam in WordPress is a lot easier than you probably think, and… Read More » The post Ultimate WordPress Spam Protection Guide – Step by Step (2026) first appeared on WPBeginner.
************
- New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAPby info@thehackernews.com (The Hacker News) on 07/08/2026 at 12:56
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server when a logged-in administrator interacts with an attacker-controlled page. Tracked as CVE-2026-64638 (CVSS score: 8.9), the
- Growing Up The Hard Wayby info@thehackernews.com (The Hacker News) on 07/08/2026 at 11:55
Open Source had a great childhood. For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once thought about who was watching. It ran the kind of lemonade stand that took IOUs from anyone who wandered up — take what you need, pay me back whenever, no need to leave a name. It was idyllic. It was also, in retrospect, a little feral. Then,
- 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containersby info@thehackernews.com (The Hacker News) on 07/08/2026 at 11:10
A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since 2008. The fix already shipped: stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148, released August 3, close it. Anyone running an older kernel with SCTP reachable should update.
- New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tablesby info@thehackernews.com (The Hacker News) on 07/08/2026 at 10:58
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Presented at Black Hat USA 2026, the research found affected behavior across independently developed implementations, including Windows and
- Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emailsby info@thehackernews.com (The Hacker News) on 07/08/2026 at 10:38
Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email. "The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic,








